VDB
Sign up
HIGH8.8

GHSA-3r32-cp7v-5wq4

Code injection in ansible semaphore

Details

An issue in ansible semaphore v.2.8.90 allows a remote attacker to execute arbitrary code via a crafted payload to the extra variables parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/ansible-semaphore/semaphore
Introduced in: 0

No fixed version published yet for github.com/ansible-semaphore/semaphore (go modules). Pin to a known-safe version or switch to an alternative.

References